forensic-technique

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted forensic evidence from various sources including disk images, memory dumps, and network captures, which may contain adversarial instructions.
  • Ingestion points: Evidence files processed via scripts/forensic_triage.py and referenced forensic artifacts (EVTX, PCAP, MFT, registry hives, memory regions) described in the references/ directory.
  • Boundary markers: The instructions lack explicit boundary markers or delimiters to differentiate between the agent's instructions and the untrusted data content being analyzed.
  • Capability inventory: The skill directs the agent to utilize a wide array of forensic tools such as volatility3, yara, capa, chainsaw, zeek, and tcpdump, which involves significant file system and diagnostic capabilities.
  • Sanitization: No specific sanitization or escaping mechanisms are mandated for processing content from external artifacts before they are incorporated into the agent's reasoning context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — forensic-technique